logo

Administrator Protection Review

ID: e68aabe2-28f8-5b1b-a60d-afabf8a6aec6

STIX ID: report--e68aabe2-28f8-5b1b-a60d-afabf8a6aec6

Feed Name: SpecterOps Blog

Threat Score
35/100

Date Published: 2025-06-18

Date Updated: 2026-04-30

Author: Adam Chester

...
...

This post examines Microsoft's Administrator Protection in Windows 11 (Shadow Admin accounts), describing how shadow accounts are created and how LSASS and Consent.exe issue their tokens. The author demonstrates that existing UAC bypass techniques (LocalAccountTokenFilterPolicy, RunOnce, and UIAccess DLL hijacks) still permit elevation or high-integrity tokens in certain scenarios, highlights allowlist and registry SID link behaviors, and discusses implications for tooling and operational security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.